Questions Flashcards
AWS service encryption enabled by default
CloudTrail Logs
AWS Region as minimum how many AZs
3
AZs have minimum how many Data Centres
1
Fault Tolerance is achieved by Scale Up or Scale Out
Scale Out
Three best practice areas for Reliability in the cloud
Foundations(AWS Config - monitors and records your AWS resource configurations),
Change Management(AWS CloudTrail, account activity),
Failure Management(CloudWatch - built for DevOps engineers, developers, site reliability engineers (SREs), and IT managers for monitoring applications and performance)
AWS Trusted Advisor
Provision your resources following AWS best practices
Cost optimization, security, fault tolerance, service limits, and performance improvement (CSSPF)
Amazon GuardDuty
Threat detection service that monitors malicious activity and unauthorized behavior
Amazon Inspector
Security Assessment - Assesses applications for exposure, vulnerabilities, and deviations from best practices
AWS CloudWatch
For devops engineers
AWS CloudTrail
For organization for governance,compliance and audit of AWS accounts
AWS Basic Support
Access to the core Trusted Advisor checks
AWS Health Dashboard
AWS Developer Support
Email-based technical support during business hours
Access to the core Trusted Advisor checks from Service Quota and basic Security checks
AWS Enterprise
Customers with concierge-like service
24x7 technical support from high-quality engineers
Designated Technical Account Manager
AWS Enterprise On-Ramp Support
Expert guidance to grow and optimize in the Cloud
Business Critical downtime < 30 mins
AWS Business Support
24x7 phone, email and chat access to technical support
Business Critical downtime < 15 mins
What provides protection at Amazon API Gateway, Amazon CloudFront or an Application Load Balancer
AWS WAF
What provides protection at Network layer and Transport layers
AWS Sheild
Receive alerts when the reservation utilization falls
AWS Budgets
Allows marketers and developers to deliver customer-centric engagement experiences
Amazon Pinpoint
Active-active configuration across regions using Managed NoSQL DB
Amazon DynamoDB with global tables
AWS Partner Network (APN)
Global partner program for technology and consulting businesses
AWS Systems Manager
Gives you visibility and control of your infrastructure on AWS
Unified user interface so you can view operational data from multiple AWS services
Enables to running commands, managing patches, and configuring servers across AWS Cloud as well as on-premises
Estimate Cost
AWS Pricing Calculator
Comprehensive cost report while running AWS services
AWS Cost and Usage report
High level cost report while running AWS services with historical data
AWS Cost Explorer
Set alert for cost and usage(utilization) limits
AWS Budgets
Dedicated Host vs Instance
BYOL(Bring your own license, like server-bound software licenses) is supported in dedicated host only
Allows to consistently deploy your instance to the same physical server is supported in dedicated host only
AWS encryption SDK
Client-side encryption library that is separate from the language–specific SDKs
SSE-S3 vs SSE-KMS
SSE-S3 = Server-side encryption with Amazon S3-Managed Keys (free)
SSE-KMS = Server-side encryption with AWS KMS keys (additional charges and has audit trail)
Encryption is enabled by default for all the objects written to Amazon S3. True or False?
True
Geolocation vs Geoproximity routing policy
Route traffic base on user location vs location of your resources
Multivalue answer routing
Upto 8 healthy records
In most cases there is no charge for inbound data transfer or data transfer between other AWS services within the same region. True or False?
True
AWS Endpoint vs AWS PrivateLink
At consumer level vs at service provider level. Both work together to provide private connection to AWS services within AWS.
However AWS PrivateLink also provides private connection of AWS services to on-premises applications
AWS site to site VPN vs Direct Connect
Connect on premise to AWS services over public internet
Vs
Connect on premise to AWS services over private network
CAF - Business perspective what are the roles?
CEO, CFO, COO, CIO, and CTO
Cloud investments accelerate your digital transformation
CAF - People perspective what are the roles?
CIO, COO, CTO, cloud director, and cross-functional and enterprise-wide leaders
(cross-functional and enterprise-wide leaders)
Bridge between technology and business
CAF - Governance perspective what are the roles?
CIO, CTO, CFO, CDO, and CRO
(CDO and CRO)
Orchestrate your cloud initiatives while maximizing organizational benefits and minimizing transformation-related risks
CAF - Platform perspective what are the roles?
CTO, technology leaders, architects, and engineers
(architects, and engineers)
Build an enterprise-grade, scalable, hybrid cloud platform
CAF - Security perspective what are the roles?
CISO, CCO, internal audit leaders, and security architects and engineers
(CISO, CCO)
Achieve the confidentiality, integrity, and availability of your data and cloud workloads
CAF - Operations perspective what are the roles?
infrastructure and operations leaders, site reliability engineers, and information technology service managers
(site reliability engineers and IT service managers )
Ensure that your cloud services are delivered at a level that meets the needs of your business
Cloud Transformation
Journey
Envision(demonstrating) ->Align(gap analysis)->Launch(delivering pilot)->Scale(expanding pilots)
(EALS)
“No upfront payment option with the standard 1-year term”
“All upfront payment option with the standard 1-year term”
“No upfront payment option with the standard 3-years term”
“Partial upfront payment option with the standard 3-years term”
What is % saving in each?
36%
40%
56%
59%
AWS SQS and SNS
Used to decouple and scale microservices, distributed systems, and serverless applications
AWS Step Functions
Coordinate multiple AWS services into serverless workflows
AWS Glue
ETL service
VPC Endpoint - Types
Interface(IP based AWS S3 and Others) and Gateway(Route table based supported by AWS S3 and DynamoDB)
SG has both Allow and Deny rules. True or False?
False, only Allow
NAT ACL has both Allow and Deny rules. True or False?
True
NAT ACL works at?
Subnet level. Its stateless
Security Group works at?
Instance(VPC) level
NAT Gateway/Instances
Allow private subnet instaces to connect to internet or other AWS Services and restrict inbout internet traffic into subnet
Services that have reservations to optimize cost
EC2, DocumentDB, RDS, ElastiCache reserved nodes and RedShift
PaaS example
EBS
IaaS example
EC2
SaaS
AWS Rekognition
AWS EMR
Bigdata
AWS Elastic Bean Stock
Deploying and scaling web applications and services